From 99eef89a9dd0b1719644c5f6c18e9b37610c47a4 Mon Sep 17 00:00:00 2001 From: Michael Freno Date: Mon, 10 Aug 2026 16:44:53 -0400 Subject: [PATCH] workflow: trim PORTING_TOKEN (paste newlines break oauth2 auth) + fail loudly when missing --- .gitea/workflows/port-to-omp.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.gitea/workflows/port-to-omp.yml b/.gitea/workflows/port-to-omp.yml index c8f0186..fd653f2 100644 --- a/.gitea/workflows/port-to-omp.yml +++ b/.gitea/workflows/port-to-omp.yml @@ -32,6 +32,10 @@ jobs: OMP_REPO: omp-deepi-research run: | set -euo pipefail + # Trim the secret: a stray newline from pasting silently breaks + # oauth2 basic-auth. Fail loudly when it is missing entirely. + PORTING_TOKEN="$(printf '%s' "${PORTING_TOKEN}" | tr -d '[:space:]')" + : "${PORTING_TOKEN:?PORTING_TOKEN secret is not set}" URL="https://oauth2:${PORTING_TOKEN}@git.freno.me/Mike/${OMP_REPO}.git" # The omp checkout lives in $RUNNER_TEMP, outside the pi checkout: # the port script refuses to write into a subdirectory of its own